Malware

How to remove “Win32/Injector.DMCL”?

Malware Removal

The Win32/Injector.DMCL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DMCL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify desktop wallpaper
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Injector.DMCL?


File Info:

crc32: ABAD827D
md5: 3da0be8e705e5f36423f7623230b4a42
name: 3DA0BE8E705E5F36423F7623230B4A42.mlw
sha1: 906013739acb29b15df867f54fb3dfc43a790f82
sha256: 2850fe826c676fef985492c8a0f189c16e8fac79aef9905a68ab1a25309356f8
sha512: 263a66e2ad56addef5dfdf179bccdb3df5a5a4909e1695d6cdaf37f4dd52f43963b8e0ec421fdeb22710fde19f56834c727e3f6e494b156003d450db492136de
ssdeep: 6144:ZOat4srzk5MUU3ODe9ls1bHdcd4J1y+TxpqBmVGIt45KZVl:oat4nMUUea9mJOmQN6
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Win32/Injector.DMCL also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10390
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Troldesh.10
CylanceUnsafe
ZillyaTrojan.Injector.Win32.480848
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.154a913e
K7GWTrojan ( 00507a3c1 )
K7AntiVirusTrojan ( 00507a3c1 )
CyrenW32/S-b0ae5394!Eldorado
SymantecRansom.Cerber!g17
ESET-NOD32a variant of Win32/Injector.DMCL
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Troldesh.10
NANO-AntivirusTrojan.Win32.Zerber.emfvfn
MicroWorld-eScanGen:Variant.Ransom.Troldesh.10
TencentMalware.Win32.Gencirc.10b5928e
Ad-AwareGen:Variant.Ransom.Troldesh.10
SophosML/PE-A + Mal/Isda-D
ComodoMalware@#324bpjc031aq
BitDefenderThetaGen:NN.ZexaF.34608.tmZfa0tgEIle
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_INJECTOR_GC090047.UVPM
McAfee-GW-EditionBehavesLike.Win32.Gupboot.fc
FireEyeGeneric.mg.3da0be8e705e5f36
EmsisoftGen:Variant.Ransom.Troldesh.10 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Inject.xbo
AviraHEUR/AGEN.1127364
eGambitUnsafe.AI_Score_66%
Antiy-AVLTrojan[Ransom]/Win32.Cerber
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.Troldesh.10
AegisLabTrojan.Win32.Inject.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Troldesh.10
AhnLab-V3Trojan/Win32.Cerber.C1831285
McAfeeTrojan-FHPS!3DA0BE8E705E
MAXmalware (ai score=80)
VBA32Hoax.Zerber
MalwarebytesMalware.AI.4137838460
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_INJECTOR_GC090047.UVPM
RisingRansom.Cerber!8.3058 (CLOUD)
YandexTrojan.GenAsa!9H4zJrc0oNo
IkarusTrojan.Win32.Injector
FortinetW32/Generic.AC.22F091!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxEAar8A

How to remove Win32/Injector.DMCL?

Win32/Injector.DMCL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment